Whew...takes a long time to go through all those scans, etc....ere is C:\fixwareout\report.txt :
HUsername "Administrator" - 05/12/2008 18:49:14 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Other
C:\WINDOWS\Temp\kdnlt.ren 73784 06/13/2007
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"MoneyStartUp"="C:\\Program Files\\Microsoft Money\\System\\Money Startup.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Here is sdfix report:
SDFix: Version 1.182
Run by Administrator on Mon 05/12/2008 at 07:19 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting SecurityProviders Value
Resetting AppInit_DLLs value
Rebooting
Checking Files :
Trojan Files Found:
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat - Contains Links to Malware Sites! - Deleted
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat - Contains Links to Malware Sites! - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049161.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049162.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049163.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049164.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049165.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049166.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049167.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049168.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049169.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049170.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049171.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049172.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049173.DLL - Deleted
C:\SYSTEM~1\_RESTO~1\RP47\A0049174.DLL - Deleted
C:\Program Files\MediaVideoCodec\install.ico - Deleted
C:\Program Files\MediaVideoCodec\MediaVideoCodec.ocx - Deleted
C:\Program Files\MediaVideoCodec\Uninstall.exe - Deleted
C:\svchost.exe - Deleted
C:\svchost2.exe - Deleted
C:\WINDOWS\binret.exe - Deleted
C:\WINDOWS\hjoqor.dll - Deleted
C:\WINDOWS\sys.log - Deleted
C:\WINDOWS\system32\drivers\atmapi.sys - Deleted
C:\WINDOWS\system32\rc.dat - Deleted
C:\WINDOWS\system32\rozmchild.dll - Deleted
C:\WINDOWS\trayicons.exe - Deleted
C:\WINDOWS\xcvwer.dll - Deleted
C:\WINDOWS\system32\wowfx.dll - Deleted
Folder C:\Program Files\MediaVideoCodec - Removed
Folder C:\Program Files\SystemDefender - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 19:27:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"="C:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe:*
isabled:BackWeb-137903"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AMERIC~1.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Owner\\Application Data\\ppldr.exe"="C:\\Documents and Settings\\Owner\\Application Data\\ppldr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Owner\\Application Data\\trant.exe"="C:\\Documents and Settings\\Owner\\Application Data\\trant.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Documents and Settings\\Owner\\Application Data\\pcpriv.exe"="C:\\Documents and Settings\\Owner\\Application Data\\pcpriv.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Owner\\Application Data\\mcrupdate.exe"="C:\\Documents and Settings\\Owner\\Application Data\\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Owner\\Application Data\\ppldr.exe"="C:\\Documents and Settings\\Owner\\Application Data\\ppldr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Owner\\Application Data\\trant.exe"="C:\\Documents and Settings\\Owner\\Application Data\\trant.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Documents and Settings\\Owner\\Application Data\\pcpriv.exe"="C:\\Documents and Settings\\Owner\\Application Data\\pcpriv.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Documents and Settings\\Owner\\Application Data\\mcrupdate.exe"="C:\\Documents and Settings\\Owner\\Application Data\\mcrupdate.exe:*:Enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sat 21 Jul 2001 94,784 ..SH. --- "C:\WINDOWS\twain.dll"
Mon 30 Aug 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe"
Mon 30 Aug 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe"
Mon 30 Aug 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe"
Thu 9 Aug 2001 64,512 A..H. --- "C:\WINDOWS\SYSTEM32\PackethSvc.exe"
Sun 16 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Finished!
and combofix report:
ComboFix 08-05-11.1 - Administrator 2008-05-12 19:40:33.1 - NTFSx86 NETWORK
Running from: C:\Documents and Settings\Administrator\Desktop\spyware stuff\ComboFix.exe
[color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\ShoppingReport
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Owner\Start Menu\XP Antivirus 2008
C:\Documents and Settings\Owner\Start Menu\XP Antivirus 2008\Uninstall XP Antivirus 2008.lnk
C:\Documents and Settings\Owner\Start Menu\XP Antivirus 2008\XP Antivirus 2008.lnk
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Uninst.exe
C:\Program Files\XP Antivirus
C:\Program Files\XP Antivirus\xpantivirus.exe
C:\Program Files\XP Antivirus\xpantivirus.exe.tmp
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\Config.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\WINDOWS\system32\nvrsma.dll
C:\WINDOWS\windisk.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-12 to 2008-05-12 )))))))))))))))))))))))))))))))
.
2008-05-12 19:07 . 2008-05-12 19:08 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-12 19:06 . 2008-05-12 19:36 <DIR> d----c--- C:\SDFix
2008-05-12 17:52 . 2008-05-12 18:53 <DIR> d----c--- C:\fixwareout
2008-05-12 14:44 . 2008-05-12 14:44 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-12 14:44 . 2008-05-12 14:45 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-12 10:22 . 2008-05-12 10:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-11 22:19 . 2008-05-11 22:22 <DIR> d-------- C:\Program Files\Wise Registry Cleaner 3
2008-05-11 21:33 . 2008-05-11 21:33 <DIR> d----c--- C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-05-11 21:31 . 2008-05-12 11:08 <DIR> d-------- C:\Program Files\AVG
2008-05-11 20:37 . 2008-05-11 20:37 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-05-11 20:37 . 2008-05-11 22:02 <DIR> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-11 20:35 . 2008-05-11 21:30 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-11 20:29 . 2007-11-20 14:57 <DIR> d----c--- C:\Documents and Settings\Administrator\WINDOWS
2008-05-11 20:29 . 2007-11-20 14:56 <DIR> d----c--- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-05-11 20:29 . 2008-05-11 20:29 <DIR> d----c--- C:\Documents and Settings\Administrator
2008-05-11 20:29 . 2008-05-12 19:42 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 19:24 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL
2008-05-12 18:52 --------- d-----w C:\Program Files\fqwypvme
2001-07-22 02:45 94,784 --sh--w C:\WINDOWS\twain.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-12-14 16:27 171448]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
AutoPlay.exe [2001-08-27 16:52:06 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"VIDC.DVSD"= miroDV2avi.DLL
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 19:43:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\SYSTEM32\nvsvc32.exe
C:\WINDOWS\SYSTEM32\HPZipm12.exe
C:\WINDOWS\SYSTEM32\wscntfy.exe
C:\WINDOWS\SYSTEM32\cscript.exe
.
**************************************************************************
.
Completion time: 2008-05-12 19:49:22 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-05-12 23:49:18
Pre-Run: 68,808,192,000 bytes free
Post-Run: 68,262,584,320 bytes free
107 --- E O F --- 2007-12-17 12:07:39
Lastly, I tried to do the hijack this but it keeps getting hung up and doesn't finish. I was able, (I think) delete the 017 lines though...
I have been booting in safe mode as it doesn't open to the user selection page as yet and I am using another computer to post results of your directions...the sick one isn't ready for internet yet..i need to load that
What would you like next, please. And ty for all so far...